CVE-2026-64353

Source
https://cve.org/CVERecord?id=CVE-2026-64353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64353
Downstream
Published
2026-07-25T08:50:12.120Z
Modified
2026-07-26T05:17:34.845231742Z
Summary
bpf: Keep dynamic inner array lookups nullable
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Keep dynamic inner array lookups nullable

An ARRAYOFMAPS can use an array created with BPFFINNERMAP as its inner map template. A concrete inner array with a different maxentries value can then replace the template.

After a successful outer map lookup, the verifier represents the resulting map pointer using the inner map template. Const-key lookup nullness elision consequently uses the template maxentries even though the runtime helper uses the concrete inner map maxentries.

Do not elide lookup result nullness for maps marked with BPFFINNERMAP, because the template maxentries does not prove that the key is in bounds for the concrete runtime map.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64353.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d2102f2f5d75a84dbab6ff890359f0bd4a18ca22
Fixed
0b92ad64d6e4bde85e6b9888404f9a7a2b65d269
Fixed
d57db0d975053e01410c54e708a85b6d32ef2ebd
Fixed
53040a81ae57cdca8af8ac36fe4e661730cf7c6b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64353.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64353.json"